Information
AlmaLinux OS 9 SSH daemon must not allow Generic Security Service Application Program Interface (GSSAPI) authentication.
GROUP ID: V-269161
RULE ID: SV-269161r1050043
GSSAPI authentication is used to provide additional authentication mechanisms to applications. Allowing GSSAPI authentication through SSH exposes the system's GSSAPI to remote hosts, increasing the attack surface of the system.
Solution
Configure the SSH daemon to not allow GSSAPI authentication.
Add the following line to "/etc/ssh/sshd_config", or uncomment the line and set the value to "no":
GSSAPIAuthentication no
Alternatively, add the setting to an included file if the line "Include /etc/ssh/sshd_config.d/*.conf" is found at the top of the "/etc/ssh/sshd_config" file:
GSSAPIAuthentication no
Restart the SSH daemon for the settings to take effect:
$ systemctl restart sshd.service